Impact
A difficult-to-exploit weakness in the Composer component of Oracle WebCenter Portal allows an attacker with low privileges but network access via HTTP to gain unauthorized control over critical data. The flaw permits creation, deletion, or modification of portal content, causing integrity breaches, and also enables a partial denial of service that can disrupt access to the portal. The technical weakness is an instance of improper authorization that lets users perform actions beyond their intended level of access.
Affected Systems
Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0 within Oracle Fusion Middleware are affected. The vulnerability is scoped to the portal product but may also impact other components that rely on Portal services.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity with significant confidentiality, integrity, and availability impact, though the exploit difficulty is high and it requires local low privilege. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly documented exploits yet. Based on the attack vector, a low‑privileged attacker connected to the network can exploit it via standard HTTP requests, making it a realistic threat if the portal is exposed to untrusted networks.
OpenCVE Enrichment